Guidelines of Countermeasures and Police Reporting for Ransomware Cases

Authors

  • Usanut Sangtongdee Teesside University

Keywords:

Ransomware, WannaCry, Petya, VoidCrypt and Spade, police report service

Abstract

Ransomware is a tool for cybercriminals who commits extortion with locked data assets for monetary purposes. Hackers create malicious software based on cryptographic technologies combined with software engineering techniques. WannaCry and Petya are malware that have damaged huge numbers of computer machines around the world over the years. Spade ransomware has recently defined an infectious attack at the Saraburi Hospital. The first priority in dealing with these extortion threats is denying payments and stopping a negotiation with criminals at all stages. No More Ransom project is an initiative to provide victims with advice and decryption tools. WannaCry, Petya and Spade remain among the top cyber threats this decade. Dealing with aggressive denial of payment is

what the experts recommend. Terminating immediately when the incident occurs also should be put in place in order to reduce the widespread infection. A defensive response is to regularly back up and update operating systems, and antivirus programs. Channels for filing a crime report are a top priority for all police countries. Connecting information from a victim as an informant is vital in an investigation to obtain intelligence, leading to the culprit.

References

Thailand Computer Emergency Response Team. 2018. ThaiCERT Annual Report 2017-2018. Bangkok: Electronic Transactions Development Agency (ETDA). (In Thai)
INTERPOL Global Complex for Innovation. 2020. ASEAN Cyberthreat Assessment 2020: Key Insights from the ASEAN Cybercrime Operations Desk. Singapore: INTERPOL.
Teelawittayakul, S. 2019. Ransomware Detection Using Machine Learning Techniques with Ransomware Attack Samples. Thesis of the Degree of Master of Science in Data Communication and Networking , King Mongkut’s University of Technology North Bangkok. (in Thai)
National Fraud & Cyber Crime Reporting Centre. January 19, 2018. RansomAware. ActionFraud. Retrieved from https://www.actionfraud. police.uk/campaign/ransomaware
No More Ransom. n.d. About the Project. Retrieved 1 October 2020 from https://www.nomoreransom.org/en/about-the-project.html
Unnoiy-Pol, C., Kulnites, N., & Wongsongja, N. 2018. The study’s framework for the significant impacts of cybercrime towards national security, public safety, national economic security, and infrastructure serving public interest. In Pidokrat, N. et.al. (Ed), Proceeding of Graduate School Conference 2018 (pp. 144-150). Bangkok, Thailand: Suan Sunandha Rajabhat University. (in Thai)
Leingbunprokong, C. 2012. Classification of malware families based on N-grams sequential pattern features. Thesis of the Degree of Master of Science in Information Technology Management, National Institute of Development Administration, Bangkok. (in Thai)
Thailand Computer Emergency Response Team. June 27, 2017. Ransomware Alert: Petya a new specie of malware which spreads the same way as WannaCry by encrypting an entire disk. Retrieved from https://www.thaicert.or.th/alerts/user/2017/al2017us002.html (in Thai)
Thailand Computer Emergency Response Team. May 13, 2017. Watch out: WannaCry Ransomware ransomware spreads through Windows vulnerabilities, update immediately. Retrieved from https://www.thaicert.or.th/alerts/user/2017/al2017us001.html (in Thai)
Mahidol University, Nakhonsawan Campus Project. September 11, 2020. Watch out! Ransomware a Severe Cyber Attack. Retrieved from https://na.mahidol.ac.th/medicalcenter/2020/09/11/ransomware/ (in Thai)
Cyber Security Plan. September 14, 2020. Spade Ransomware. Retrieved from https://webcache.googleusercontent.com/search?q=cache:1_ui7jHCTEYJ:https://www.cybersecurityplan.org/spade-ransomware/+&cd=4&hl=en&ct=clnk&gl=th
Sonic Wall. August 14, 2020. VoidCrypt Ransomware Actively Spreading in the Wild. Retrieved from https://securitynews.sonicwall.com/xmlpost/voidcrypt-ransomware-actively-spreading-in-the-wild/
Thairath Online. May 20, 2017. Alert! The 191 Centre was attacked by 'ransomware', many people could not report. Retrieved from https://www.thairath.co.th/news/crime/947410 (in Thai)
Technology Crime Suppression Division. n.d. Report a Lead/Crime. Retrieved October 1, 2020 from https://tcsd.go.th/report-a-lead-2/?lang=en
1212 Online Complaint Center. n.d. Report a Complaint. Retrieved October 1, 2020 from https://tcsd.go.th/report-a-lead-2/?lang=en
Lipson, F. September 27, 2019. Exclusive: scam victims ignored by police fraud reporting system. In Which. Retrieved from https://www.which.co.uk/news/2019/09/exclusive-scam-victims-ignored-by-police-fraud-reporting-system/

Downloads

Published

2021-04-01

How to Cite

Sangtongdee, U. (2021). Guidelines of Countermeasures and Police Reporting for Ransomware Cases. Sahasat: Journal of Social Sciences and Humanities, 21(1), 26–44. retrieved from https://so02.tci-thaijo.org/index.php/sahasart/article/view/245102

Issue

Section

Academic Article